An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers to access resources (that are not otherwise accessible without proper authentication) via capture-replay. Physically proximate attackers can use this information to unlock unauthorized Tzumi Electronics Klic Smart Padlock Model 5686 Firmware 6.2.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-06-11T17:43:26

Updated: 2019-06-14T17:06:04

Reserved: 2019-04-18T00:00:00


Link: CVE-2019-11334

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-06-11T18:29:00.957

Modified: 2023-03-24T18:06:12.273


Link: CVE-2019-11334

JSON object: View

cve-icon Redhat Information

No data.

CWE